On Sat, 22 Apr 2006 20:50:15 PDT, Crispin Cowan said: >> What happens if I ln /bin/stty /tmp/evilstty, then exploit >> vulnerability in stty? A crucial point here is that the 'ln' and the actual exploit don't have to be firmly attached to each other... If you can get *any* unconfined user to do that 'ln' (Hmm... have you checked if your tar/cpio/pax/etc have been patched to prohibit this when you extract an archive?), then the exploit can be run *even in a domain that can't do the ln that set it up*. > This is a really basic misunderstanding of AppArmor. All unconfined > processes are considered trusted, so attacks that suppose an unconfined > user did something very evil/stupid are not interesting. Unfortunately, in the *real* world, "unconfined user accidentally runs malware that sets up the conditions for a later exploit" is an actual real problem. I'm sorry to see that it's just swept under the rug as "not interesting". Now, if you changed "not interesting" to "so damned hard we couldn't figure out how to deal with it", I'd have a bit of sympathy for the position... ;)
Attachment:
pgpky21wgaXOJ.pgp
Description: PGP signature
- Follow-Ups:
- References:
- Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks
- From: Török Edwin <[email protected]>
- Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks
- From: Stephen Smalley <[email protected]>
- Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks
- From: Christoph Hellwig <[email protected]>
- Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks
- From: Stephen Smalley <[email protected]>
- Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks
- From: Christoph Hellwig <[email protected]>
- Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- From: James Morris <[email protected]>
- Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- From: Greg KH <[email protected]>
- Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- From: Alan Cox <[email protected]>
- Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- From: [email protected]
- Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- From: Crispin Cowan <[email protected]>
- Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- From: Pavel Machek <[email protected]>
- Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- From: Crispin Cowan <[email protected]>
- Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks
- Prev by Date: Re: [ckrm-tech] [RFC] [PATCH 00/12] CKRM after a major overhaul
- Next by Date: Re: unix socket connection tracking
- Previous by thread: Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- Next by thread: Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks)
- Index(es):